
Embed Google Drive Security & Risk Analysis
wordpress.org/plugins/embed-google-driveEmbed a link and preview of Google Drive Documents by pasting a shared document link into the editor.
Is Embed Google Drive Safe to Use in 2026?
Generally Safe
Score 100/100Embed Google Drive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "embed-google-drive" plugin v1.2.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and ensuring all outputs are properly escaped. Furthermore, there is no recorded vulnerability history, including no known CVEs, which suggests a history of secure development and maintenance. The absence of dangerous functions, file operations, and external HTTP requests (beyond one, which needs context but is not flagged as dangerous) also contributes to a favorable impression.
However, significant concerns arise from the attack surface analysis. The plugin exposes two REST API routes without any permission callbacks. This means that any unauthenticated user could potentially interact with these endpoints, creating a substantial security risk. While the static analysis found no dangerous functions or taint flows with unsanitized paths, the lack of authentication on these entry points is a critical oversight that could lead to various vulnerabilities if the functionality exposed by these endpoints is not inherently benign or is susceptible to manipulation. The complete absence of nonce checks and capability checks further exacerbates this risk, as there are no mechanisms in place to verify the user's identity or authorization for these API calls.
In conclusion, while the plugin's internal code practices regarding SQL and output escaping are commendable, and its vulnerability history is clean, the exposed REST API endpoints without any authentication represent a critical weakness. This lack of authorization checks on entry points is a serious security flaw that could allow unauthorized actions or information disclosure. Addressing this vulnerability by implementing proper permission checks on the REST API routes should be the highest priority.
Key Concerns
- REST API routes without permission callbacks
- REST API routes without authentication
- No nonce checks
- No capability checks
Embed Google Drive Security Vulnerabilities
Embed Google Drive Code Analysis
Output Escaping
Embed Google Drive Attack Surface
REST API Routes 2
WordPress Hooks 4
Maintenance & Trust
Embed Google Drive Maintenance & Trust
Maintenance Signals
Community Trust
Embed Google Drive Alternatives
Embed Files from Google Drive
google-drive-embedder
Browse for Google Drive documents and embed directly in your posts/pages. Extends Google Apps Login plugin so no extra user auth required.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
Document Embedder – Embed PDFs, Word, Excel, and Other Files
document-emberdder
Document Embedder lets you display PDF, DOCX, PPTX, XLSX, and other files in WordPress sites with a responsive viewer and optional download button.
WP Calameo
wp-calameo
This plugin allows to embed Calaméo publications in blog posts. Copy the WordPress embed code and paste it into your post.
Embed Google Drive Developer Profile
19 plugins · 119K total installs
How We Detect Embed Google Drive
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/embed-google-drive/v1/get-preview-url